Tunneling Data and Commands Over DNS to Bypass Firewalls
zeltser.com
zeltser.com
Additionally, if they have aggressive egress filtering, its likely that the only DNS communication will be via an internal resolver which is going to be monitored - iodine is going to leave a LOT of shit in those logs.
It's also a great source of information when monitoring egress communication, so I would just make sure you know what you're doing.
Neither is putting in place a firewall that makes people need to circumvent it to get their jobs done. If you work at the NSA, sure, it makes sense that all access is heavily restricted. (Though if you work at the NSA, please reconsider what you're doing with your life.) But if you work at an ordinary company, and doing your job (note: not goofing off, but actually doing your job) requires you to work around the corporate firewall, that's a serious policy problem. And the answer isn't to sit on your hands until IT fixes the firewall, because IT departments invariably seem to have far too many people in them that forget that you can't create security by preventing work. A system encased in concrete is secure, but not useful.
If your job involves idling on Freenode maybe take it up with management?
EDIT: phrasing
Second, even when your metric is security, creating a policy that people have to circumvent to get their job done seems likely to reduce security.
> when it comes to ensuring what data comes in and leaves your environment there's little choice
The concept of your environment having an "inside" and an "outside" is dangerous. Better to assume that "inside" is just as hostile as "outside", and avoid having any insecure internal services or resources. Use TLS/HTTPS everywhere internally, require authentication for internal services, and otherwise make sure that an attacker gains nothing by compromising an end-user system except what's on that end-user system.
> If your job involves idling on Freenode
Forget "idling"; participating effectively in many Open Source projects (whether developing them or getting support for them) requires the ability to get on IRC.
> maybe take it up with management
Short of C-level executives, management rarely has the ability to change IT policy.
I agree with what you say regarding perimeter security, a concept quickly decreasing in relevance in today's environments. Unfortunately, when you have thousands of people working for you that don't know how to computer, you have to take steps to ensure that the data and functionality that they're handling remains protected.
Additionally, a large amount of attack surface exists on the client side, and with these two factors at play you're dealing with a lot of non-trivial trust relationships within your organisation.
Yes, ideally every system would be an island, and everyone who was supposed to operate it could do so securely and competently enough that they'd realise if something was wrong.
Until then, corporate workstations live in a locked down world where all external access is monitored and scrutinised.
Continuing to circumvent the corporate controls puts your job and possibly your career in jeopardy. Likely you will impact your colleagues as well with even more onerous restrictions.
It's not security, it's security-by-the-checkbox, that doesn't prevent them having the whole intranet on a single shared drive, use outlook, flash, java etc etc. Oh, and such a braindead password policy (like, 6 of them) that everyone has to keep them on postits anyway.
(signed, a former firewall piercer extraordinaire)
((I got so fed up with one customer's stupid firewall rules that I bought a dial-up subscription to Earthlink and an adapter that would let me hook my modem up to the handset of their digital phone.))
(((Holy shit! Earthlink still has dialup service!)))
Edit: From the site's blurb on Security: "iodine uses challenge-response login secured by MD5 hash." Sorry, but MD5 as 'secure' died a long time ago.
It seems like this pattern could be recognized behind the firewall. How often would a real Internet client resolve hundreds or thousands of sub-hosts in a short timeframe?
For instance, on this link on HN: https://medium.com/@bchesky/7-rejections-7d894cbaa084
It loads <some random subdomain>.cloudfront.net - and it changes every reload for me. For instance, d262ilb51hltx0.cloudfront.net, dnqgz544uhbo8.cloudfront.net, d262ilb51hltx0.cloudfront.net.
I suppose if the malware wanted to be more stealthy, it could slow transfers way down, intermix unrelated queries and spread the tunnel across multiple unrelated controlled domains.
This doesn't work for many hotel paywalls, because they would have a catch-all rule for all DNS A queries (resolving to a local IP of authenticating proxy) and block everything else. And the reason is exactly because of the DNS tunneling, which was making rounds in p2p circles as far back as 2005 if not earlier.
(I'm not doubting they do this, just saying it seems very hacky...)
Other solutions use proxy configuration detection to redirect people to a proxy that first asks for authentication/payment. (wpad file)
Both solutions are kind of hacky, but they work for more or less all devices.
Iodine seems to be a bit more complex as the default configuration doesn't work in that environment.
[1] https://play.google.com/store/apps/details?id=air.com.mail4h...